Use this screen to define how SCIM delete requests are handled within your user datastore.

If the group support option is enabled, when PingFederate receives a SCIM delete request for a group, it always removes the specified group from the datastore.

Delete or Disable Users

This screen appears only if you are configuring an LDAP user store for provisioning.

  • Select Disable User to make the user inactive within the datastore. This approach might be preferred in situations where accounts must be retained for auditing reasons.
    In order to be SCIM compliant when deleting users, PingFederate returns an HTTP 404 response code for all subsequent operations related to the user-effectively treating the user as if they have been deleted from the LDAP user store (see the SCIM specifications).

    If the user is disabled through another method, PingFederate still treats that user as if they have been deleted and returns HTTP 404 response codes for all subsequent requests.

  • Select Permanently Delete User to remove the user from the datastore.